Sec Guy
Sec Guy
0
Real cybersecurity training for the real world. The podcast takes complex theories of CompTIA Security+ and SecAI+ and translates them into actionable skills. It covers topics like AI Security, Network Defense, and the future of cyber, helping listeners fight off Prompt Injection attacks or get their first IT job.
Епизоде
-
CompTIA Security+ Full Course 2026 17.09.2026 5минWelcome to the Sec Guy Channel and the start of your journey to becoming a cybersecurity professional! 🛡️ This is the first video in our comprehensive training series designed to help you pass the new CompTIA Security+ (SY0-701) exam.In this foundational video, "Exam Overview," we're breaking down everything you need to know before you start studying the core content. Understanding the exam logistics is the first step to success!🔑 What We Cover:Exam Logistics: Format, number of questions, and scoring.PBQs & Multiple Choice: What to expect from different question types.Exam Objectives: A high-level look at the six domains you need to master.Study Tips: Strategies for approaching the exam effectively.Whether you're new to IT or looking to formalize your security knowledge, this series is for you.🔔 Don't forget to Like, Comment, and Subscribe for more cybersecurity training! Hit the notification bell so you don't miss the next video in this series.➡️ Next Video in the Series: [Link to next video when available]📚 Resources Mentioned:CompTIA Security+ (SY0-701) Objectives: https://www.comptia.org/en-us/certifications/security/Recommended Study Materials: Cheat Sheet: https://mega.nz/file/rVdWnQCL#oL80-0nSlu3_bs35fc52CO8UGCLmkqBC7way0CDKgZM Practice TestDomain 1: Test A: https://mega.nz/file/XYNySIYA#IG57yLOhdlD5VvMd1AdHTXaD9fVJg4ISsK7t9LRBIjQ Domain 1: Test B: https://mega.nz/file/3IsSWQyD#Ak4Y0MOfqzOXBdSjTu0twaDsQqG-5OKQrwo0m8vYFZ4 Domain 1: Test C: https://mega.nz/file/6BVghCYS#vycOnNv3KkRRK0e7MMvSQ0gSFTw05FgmgSOlAMOjGcA Domain 1: Test D: https://mega.nz/file/jZMkGLII#wc74MYCpBKWkM44mLFKcX4mrTngr-Q1bQ5rE1Xk6Xso Connect with My Sec Guy Channel:📘 Facebook: https://www.facebook.com/share/1HGdh1m51U/ #CompTIA #SecurityPlus #SY0701 #CybersecurityTraining #ITCertification #MySecGuy #ExamOverview #CyberSec #ITSecurityOriginal Sec Guy video: https://www.youtube.com/watch?v=PjvDwhUA_GA -
Mastering Security Controls: Preventive, Detective, & Corrective 17.09.2026 5минFirewalls aren't enough. To build a true defense-in-depth strategy, you need to understand the three pillars of security controls: Preventive, Detective, and Corrective. In this video, Sec Guy breaks down how these controls work together to secure your network, using real-world analogies to make the concepts stick for your exam and your career.[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ (SY0-701)[ ] Domain 1.2: Types of Security Controls (Preventive, Detective, Corrective)CISSP[ ] Domain 3: Security Architecture (Control Selection)[ ] Domain 7: Security Operations (Foundational Concepts)CISM[ ] Domain 3: Information Security Program (Control Design & Implementation)CRISC[ ] Domain 3: Risk Response and Reporting (Control Design)CCSP[ ] Domain 1: Cloud Concepts & Architecture (Control Frameworks)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Enterprise Security Controls)GIAC GSEC (SANS)[ ] Network Security Essentials: Defense in Depth & Access ControlsAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (Security Groups/NACLs as Preventive Controls)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Understanding Defenses to Bypass Them)CEH (Certified Ethical Hacker)[ ] Domain 1: Information Security Overview (Defense in Depth Fundamentals)SecAI+[ ] AI Security Fundamentals: Implementing Guardrails (Preventive Controls)[Timestamps]0:00 - Intro: The 3 Types of Security Controls0:58 - Preventive Controls: The Frontline Defenders (Firewalls, MFA)2:27 - Detective Controls: Spotting the Suspicious (IDS, Logs)3:42 - Corrective Controls: Fixing the Damage (Backups, Patching)4:42 - Summary: Building Defense in Depth5:32 - Outro: Stay Safe, Stay Secure.#CompTIASecurityPlus #CISSP #CISM #CyberSecurity #InfoSec #SecurityControls #SecGuy #SY0701 #NetworkDefense #CRISC #CCSP #ITTrainingOriginal Sec Guy video: https://www.youtube.com/watch?v=cjMqzX1Vs0Q -
What is the CIA Triad? The Foundation of Cyber Security 17.09.2026 4минConfidentiality, Integrity, and Availability aren't just buzzwords—they are the backbone of every security strategy you will ever build. In this video, Sec Guy breaks down the "CIA Triad" with real-world examples (like hospital outages and bank hacks) to show you exactly how these three principles keep systems secure and why they are the first thing tested on your exam.[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ (SY0-701)[ ] Domain 1.1: General Security Concepts (CIA Triad)CISSP[ ] Domain 1: Security and Risk Management (Security Concepts)CISM[ ] Domain 1: Information Security Governance (Information Security Concepts)CRISC[ ] Domain 1: Governance (Organizational Goals & Objectives)CCSP[ ] Domain 1: Cloud Concepts & Architecture (CIA in the Cloud)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Foundational Principles)GIAC GSEC (SANS)[ ] Information Security Fundamentals: The CIA TriadAWS CSS (Certified Security – Specialty)[ ] Domain 1: Threat Detection and Incident Response (Impact on CIA)Pentest+ (CompTIA)[ ] Domain 1: Planning and Scoping (Confidentiality & Integrity Impact)CEH (Certified Ethical Hacker)[ ] Domain 1: Information Security Overview (Essential Terminology)SecAI+[ ] AI Security Fundamentals: Protecting Model Confidentiality & Integrity[Timestamps]0:00 - Intro: The Backbone of Security0:32 - Real-World Example: The Hospital Hack1:52 - Confidentiality: Keeping Secrets Secret (Encryption, MFA)2:34 - Integrity: Trusting the Data (Hashing, Digital Signatures)3:18 - Availability: Keeping Systems Running (Backups, Redundancy)4:06 - Summary: The Foundation of Every Control4:17 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=hids4CADb6M -
Mastering Access Control: RBAC, MAC, DAC & The AAA Framework 17.09.2026 10минIf you can't prove who you are, what you're allowed to do, and track what you did—you have no security. In this video, Sec Guy breaks down the AAA Framework (Authentication, Authorization, Accounting) and explains the critical differences between RBAC, MAC, and DAC that you must know for your exam and your career.[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ (SY0-701)[ ] Domain 1.3: Identity and Access Management (Authentication Factors, MFA, AAA)[ ] Domain 1.4: Access Control Schemes (RBAC, MAC, DAC)CISSP[ ] Domain 5: Identity and Access Management (IAM Lifecycle, Access Control Models)CISM[ ] Domain 3: Information Security Program (Identity Management & Access Control)CRISC[ ] Domain 2: IT Risk Assessment (IAM Vulnerabilities)CCSP[ ] Domain 4: Cloud Application Security (Identity & Access Management in Cloud)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Enterprise IAM Strategies)GIAC GSEC (SANS)[ ] Access Control & Password Management: AAA, MFA, & Access ModelsAWS CSS (Certified Security – Specialty)[ ] Domain 3: Infrastructure Security (IAM Policies & Roles)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Attacking Authentication & Authorization)CEH (Certified Ethical Hacker)[ ] Domain 6: System Hacking (Privilege Escalation & Password Cracking)SecAI+[ ] AI Security Fundamentals: Biometric Authentication & AI-Driven IAM[Timestamps]0:00 - Intro: The 3 Pillars of Access Control0:35 - The Airport Analogy: Understanding AAA1:00 - Authentication: Proving Who You Are (MFA vs. 2FA)2:52 - Authorization: What Are You Allowed To Do?3:15 - Access Control Models: RBAC vs. DAC vs. MAC4:50 - Principle of Least Privilege & Separation of Duties6:02 - Accounting: Logging & Non-Repudiation (SIEM)8:06 - Digital Signatures: Integrity & Authenticity9:08 - Summary: AAA Sec Guy Style9:55 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=eJm-Na32ljE -
Zero Trust Architecture Explained (CompTIA Security+, CISSP, CEH, SecAI+, GIAC) 17.09.2026 11мин"Trust but Verify" is a failed strategy. In today's cloud-native world, the only safe assumption is "Never Trust, Always Verify." In this deep dive, Sec Guy unpacks the NIST 800-207 Zero Trust Architecture, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP), and shows you how to stop lateral movement dead in its tracks.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.2: Security Concepts (Zero Trust Control Plane/Data Plane)CISSP[ ] Domain 3: Security Architecture (Zero Trust Principles)[ ] Domain 5: Identity & Access Management (Just-in-Time Access)CISM[ ] Domain 2: Information Risk Management (Reducing Attack Surface)CRISC[ ] Domain 1: Governance (Zero Trust Strategy Implementation)CCSP[ ] Domain 1: Cloud Concepts (Zero Trust in Cloud Architecture)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Implementing ZTNA & SASE)GIAC GSEC (SANS)[ ] Access Control & Password Management: Zero Trust Network AccessAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (Micro-segmentation & Least Privilege)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Lateral Movement in Zero Trust)CEH (Certified Ethical Hacker)[ ] Domain 6: System Hacking (Bypassing Micro-segmentation)SecAI+[ ] AI Security Fundamentals: Behavioral Biometrics & AI-Driven Trust Algorithms[Timestamps]0:00 - Intro: The Death of the Perimeter1:00 - The Core Principle: Never Trust, Always Verify (NIST 800-207)1:26 - Pillar 1: Assume Breach & Micro-segmentation2:20 - Pillar 2: Verify Explicitly (Context, Health, & Biometrics)3:05 - Pillar 3: Least Privilege Access (JIT Access)4:00 - Architecture Deep Dive: Control Plane vs. Data Plane4:40 - The Logical Components: Policy Engine (PDP) & Enforcement (PEP)6:45 - Continuous Adaptive Risk & Trust Assessment (CARTA) & AI7:33 - Technologies: ZTNA, SDP, & SASE8:44 - Non-Human Identities: Securing AI Agents & APIs10:00 - Summary: Strategy Over Products11:15 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=EWcfkEC4z8Y -
Physical Security in the AI Era 17.09.2026 7минWe spend millions on firewalls, but if an insider can walk out the front door with your AI models in a backpack, your security program has failed. In this video, Sec Guy breaks down the Google AI theft case, explains why "Degaussing" destroys hard drives but fails on SSDs, and covers the critical exam concepts of CPTED, Man Traps, and Faraday Cages.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+[ ] Domain 2.4: Physical Security Controls (Man Traps, Faraday Cages, Air Gaps)[ ] Domain 3.3: Data Destruction and Disposal (Degaussing vs. Shredding)CISSP[ ] Domain 3: Security Architecture (CPTED, Fire Suppression Classes)[ ] Domain 7: Security Operations (Personnel Safety & Physical Access)CISM[ ] Domain 2: Information Risk Management (Physical Threats to Availability)CRISC[ ] Domain 2: IT Risk Assessment (Environmental Controls & Power Failure)CCSP[ ] Domain 2: Cloud Data Security (Data Center Physical Security Layers)SecurityX (CompTIA)[ ] Domain 3.0: Security Operations (Physical Breach Response)GIAC GSEC (SANS)[ ] Physical Security: Access Control, Lighting (Lux), & Perimeter DefenseAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (Shared Responsibility: Physical Layer)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (RFID Cloning, Tailgating, Badge Cloning)CEH (Certified Ethical Hacker)[ ] Domain 2: Footprinting (Physical Reconnaissance)SecAI+[ ] AI Security Fundamentals: Protecting AI Hardware (GPUs) & Model Weights[Timestamps]0:00 - Intro: The Google AI Theft (Insider Threat)1:04 - Perimeter Security: CPTED & Lighting (Lux Levels)2:20 - Authentication: Badge Cloning (Flipper Zero) & Man Traps3:06 - Critical Exam Question: Fail Safe vs. Fail Secure (Human Safety)3:30 - Securing AI Hardware: Caged Racks & Hot/Cold Aisles4:30 - Environmental Controls: Fire Suppression (FM-200) & UPS5:25 - High Security: Air Gaps & Faraday Cages6:00 - Data Destruction: Degaussing (HDD) vs. Shredding (SSD)6:42 - Summary: Physical Security is the Foundation7:02 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=Kc9uIjwQDPU -
Hashing Explained - Digital Fingerprints & Data Integrity 17.09.2026 4минHashing is NOT encryption—it's a one-way "meat grinder." In this video, Sec Guy explains the "Avalanche Effect," why MD5 and SHA-1 are dead, and how hackers use Rainbow Tables to crack unsalted passwords in milliseconds. If you don't understand the difference between a collision and a salt, you are not ready for your exam.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.1: Cryptographic Concepts (Hashing, Salting, Key Stretching)[ ] Domain 4.1: Monitoring (File Integrity Monitoring / FIM)CISSP[ ] Domain 3: Security Architecture (One-Way Functions, Integrity, Message Digests)[ ] Domain 5: Identity & Access Management (Secure Password Storage)CISM[ ] Domain 2: Information Risk Management (Data Integrity Controls)CRISC[ ] Domain 2: IT Risk Assessment (Compromise of Data Integrity)CCSP[ ] Domain 2: Cloud Data Security (Encryption & Hashing Standards)SecurityX (CompTIA)[ ] Domain 2.0: Security Architecture (Cryptographic Implementations & Algorithms)GIAC GSEC (SANS)[ ] Cryptography: Hash Functions, Integrity, & Rainbow TablesAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (Data Integrity & Storage Security)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Password Cracking, Hash Collisions, Rainbow Tables)CEH (Certified Ethical Hacker)[ ] Domain 4: Cryptography (Hash Algorithms & Cryptanalysis Tools)SecAI+[ ] AI Security: Data Integrity (Hashing Training Data to Prevent Poisoning)[Timestamps]0:00 - Intro: Hashing = Integrity0:28 - The Golden Rule: One-Way Function (The "Meat Grinder")0:50 - The Avalanche Effect (Changing 1 Bit changes Everything)1:21 - Algorithms: MD5 vs. SHA-1 vs. SHA-256 (The Gold Standard)1:56 - Collisions: When Two Files Have the Same Hash2:20 - Password Security: How Rainbow Tables Work2:50 - The Solution: Salting Passwords3:15 - Summary: One-Way, Integrity, & Salt3:44 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=YjHTBFe7R14 -
Encryption Explained: Symmetric vs. Asymmetric 17.09.2026 5минIf you can't explain the difference between a "Private Key" and a "Public Key," you will fail your exam. In this video, Sec Guy breaks down the two main families of encryption, explains why we use Symmetric for speed (AES) and Asymmetric for security (RSA/ECC), and gives you the "23 BRAIDS" mnemonic to memorize every algorithm instantly.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.1: Cryptographic Concepts (Symmetric, Asymmetric, Key Exchange)[ ] Domain 5.4: Data Protection (Data at Rest, In Transit, In Use)CISSP[ ] Domain 3: Security Architecture (Cryptographic Systems: AES, RSA, ECC)CISM[ ] Domain 2: Information Risk Management (Encryption Controls)CRISC[ ] Domain 2: IT Risk Assessment (Data Leakage Risks)CCSP[ ] Domain 2: Cloud Data Security (Encryption Strategies for Cloud Storage)SecurityX (CompTIA)[ ] Domain 2.0: Security Architecture (Implementing Cryptography)GIAC GSEC (SANS)[ ] Cryptography: Algorithms & DeploymentAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (KMS, S3 Encryption, TLS)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Weak Encryption & Downgrade Attacks)CEH (Certified Ethical Hacker)[ ] Domain 4: Cryptography (Cryptanalysis & PKI)SecAI+[ ] AI Security: Encrypting Model Weights & Training Data (Data at Rest)[Timestamps]0:00 - Intro: The Vault (Confidentiality)0:30 - Symmetric Encryption: The "House Key" (Fast & Simple)1:00 - The Key Exchange Problem (Out-of-Band)1:18 - Mnemonic: "23 BRAIDS" (Symmetric Algos: Twofish, Blowfish, AES, DES)1:40 - Mnemonic: "DEREK Q" (Asymmetric Algos: Diffie-Hellman, RSA, ECC, Quantum)1:49 - AES: The Gold Standard for Hard Drives2:17 - Asymmetric Encryption: The "Mailbox" (Public/Private Keys)3:02 - RSA vs. ECC (Why Mobile Phones use ECC)3:46 - Hybrid Encryption: How HTTPS Works (Best of Both Worlds)4:08 - Data States: At Rest, In Transit, In Use4:39 - Summary: AES for Bulk, RSA/ECC for Exchange4:56 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=cA3vvpmWeI0 -
Security through Obscurity? Steganography & Obfuscation Explained 17.09.2026 3мин"Security through Obscurity" is a delay tactic, not a defense strategy. In this video, Sec Guy explains why Obfuscation is different from Encryption, how hackers use Steganography to hide malware inside innocent JPEGs, and why Tokenization is the secret weapon for passing your PCI-DSS audits.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.2: Security Concepts (Obfuscation vs. Encryption)[ ] Domain 2.3: Indicators of Malicious Activity (Steganography as an IOC)CISSP[ ] Domain 3: Security Architecture (Steganography & Covert Channels)[ ] Domain 8: Software Development Security (Code Obfuscation)CISM[ ] Domain 2: Information Risk Management (Data Masking & Privacy Controls)CRISC[ ] Domain 2: IT Risk Assessment (Data Leakage via Covert Channels)CCSP[ ] Domain 2: Cloud Data Security (Tokenization & Masking)SecurityX (CompTIA)[ ] Domain 2.0: Security Architecture (Data Privacy Techniques)GIAC GSEC (SANS)[ ] Cryptography: Steganography & Obfuscation TechniquesAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (Tokenization for Compliance)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Evasion via Obfuscation)CEH (Certified Ethical Hacker)[ ] Domain 6: System Hacking (Steganography Tools & Detection)SecAI+[ ] AI Security: Obfuscating Training Data (Privacy Preserving AI)[Timestamps]0:00 - Intro: Security through Obscurity?0:38 - The Golden Rule: Obfuscation is NOT Encryption1:04 - Technique 1: Steganography (Hiding Data in Images/Audio)1:29 - Technique 2: Tokenization (PCI-DSS & Compliance)1:53 - Technique 3: Data Masking (Privacy & Usability)2:10 - Technique 4: Code Obfuscation (Protecting IP)2:30 - The Attack: Weaponizing Obfuscation (PowerShell & DNS)3:08 - How to Practice: The Sec Guy Steganography Lab3:35 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=BLXbe7vz6Sw -
Why Blockchain is Replacing Your Social Security Number 17.09.2026 3минYour Social Security Number is a password you can never change—and that is a security nightmare. In this video, Sec Guy explains why the future of identity isn't a static number in a database, but a cryptographic key in your wallet. We break down how Blockchain creates an immutable "Distributed Ledger" and how Self-Sovereign Identity (SSI) eliminates the single point of failure that hackers love.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.1: Cryptographic Concepts (Blockchain, Distributed Ledger)[ ] Domain 1.3: Identity and Access Management (Decentralized Identity)CISSP[ ] Domain 3: Security Architecture (Distributed Systems & Consensus Models)[ ] Domain 5: Identity and Access Management (Federated Identity & SSI)CISM[ ] Domain 2: Information Risk Management (Emerging Technologies Risk)CRISC[ ] Domain 2: IT Risk Assessment (Risks of Centralized vs. Decentralized Data)CCSP[ ] Domain 1: Cloud Concepts (Blockchain as a Service - BaaS)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Implementing Blockchain for Integrity)GIAC GSEC (SANS)[ ] Cryptography: Blockchain Applications & IntegrityAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (Immutable Storage & Ledger Databases)Pentest+ (CompTIA)[ ] Domain 1: Planning and Scoping (Blockchain Attack Surfaces - 51% Attack)CEH (Certified Ethical Hacker)[ ] Domain 4: Cryptography (Blockchain Fundamentals)SecAI+[ ] AI Security: Proving Content Authenticity via Blockchain (C2PA)[Timestamps]0:00 - Intro: Bitcoin is an App, Blockchain is the OS0:35 - The Problem: SSNs are Static Passwords1:12 - Distributed Ledger Technology (DLT) & Immutability1:33 - Consensus Models: Why You Can't Hack the Chain1:53 - Decentralized Identity (DID) & Self-Sovereign Identity (SSI)2:20 - The Shift: From Database World to Wallet World2:42 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=MQNNVN_4AYc -
Digital Signatures Explained: Non-repudiation, Hashing, Private Keys 17.09.2026 3минA digital signature is NOT just an image of your name on a PDF. It is a mathematical proof that guarantees three things: Authentication, Integrity, and Non-Repudiation. In this video, Sec Guy explains the exact workflow of signing a document (Hash - Encrypt with Private Key) and why this process makes it legally impossible for a sender to say "It wasn't me."🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.1: Cryptographic Concepts (Digital Signatures, Non-Repudiation)[ ] Domain 1.3: Identity and Access Management (Authentication Proof)CISSP[ ] Domain 3: Security Architecture (Digital Signatures & Message Digests)[ ] Domain 4: Communication & Network Security (Secure Email Standards - S/MIME)CISM[ ] Domain 2: Information Risk Management (Data Integrity & Non-Repudiation Controls)CRISC[ ] Domain 2: IT Risk Assessment (Risks of Repudiation)CCSP[ ] Domain 2: Cloud Data Security (Data Integrity & Origin Authentication)SecurityX (CompTIA)[ ] Domain 2.0: Security Architecture (Implementing PKI & Digital Signatures)GIAC GSEC (SANS)[ ] Cryptography: Digital Signatures & Non-RepudiationAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (Code Signing & Data Integrity)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Forging Signatures / Hash Collisions)CEH (Certified Ethical Hacker)[ ] Domain 4: Cryptography (Public Key Infrastructure & Signing)SecAI+[ ] AI Security: Model Signing (Verifying the Origin of AI Models)[Timestamps]0:00 - Intro: Digital Signatures vs. Wet Ink0:32 - The 3 Guarantees: Authentication, Integrity, Non-Repudiation0:46 - Step 1: Hashing the Data (Creating the Fingerprint)1:16 - Step 2: Encrypting the Hash with the PRIVATE Key1:38 - Step 3: Verification with the PUBLIC Key2:07 - Non-Repudiation: Why You Can't Deny It in Court2:34 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=49wx9ENRRo4 -
Threat Actors & Motivations 17.09.2026 4минIf you don't know who is attacking you, you are just chasing ghosts. In this video, Sec Guy maps the adversary landscape—from highly funded Nation States (APTs) like Salt Typhoon to financially motivated Organized Crime groups like Scattered Spider. We also reveal why the "Insider Threat" and "Shadow IT" might be more dangerous to your organization than any elite foreign hacker.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ (SY0-701)[ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Attributes & Motivations)CISSP[ ] Domain 1: Security and Risk Management (Threat Modeling & Risk Assessment)CISM[ ] Domain 1: Information Security Governance (Threat Landscape Analysis)CRISC[ ] Domain 2: IT Risk Assessment (Threat Identification & Insider Risk)CCSP[ ] Domain 1: Cloud Concepts (Shadow IT Risks)SecurityX (CompTIA)[ ] Domain 3.0: Security Operations (Threat Hunting & Attribution)GIAC GSEC (SANS)[ ] Incident Handling & Threat Intelligence: Threat ActorsAWS CSS (Certified Security – Specialty)[ ] Domain 1: Threat Detection (Identifying Unauthorized Access/Shadow IT)Pentest+ (CompTIA)[ ] Domain 1: Planning and Scoping (Adversary Emulation)CEH (Certified Ethical Hacker)[ ] Domain 1: Information Security Overview (Cyber Kill Chain & Threat Concepts)SecAI+[ ] AI Security: Adversarial Machine Learning (Nation State AI Threats)[Timestamps]0:00 - Intro: Mapping the Adversary0:23 - Nation States (APTs): Espionage & Long Dwell Time (Salt Typhoon)1:03 - Organized Crime: Financial Motivation (Scattered Spider)1:27 - Hacktivists: Political Disruption (Belarusian Cyber Partisans)1:51 - Script Kiddies: Unskilled but Noisy2:09 - Insider Threats: Malicious vs. Negligent (The "Clicker")2:38 - Shadow IT: The Silent Killer of Compliance3:32 - Interview Challenge: Who is the Biggest Risk? (Elite Hacker vs. Admin)4:09 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=5Q00hR5OFBw -
Security+ Domain 1: Question Walkthrough 17.09.2026 7минJoin Sec Guy for an in-depth review of Domain 1 for the CompTIA Security+ (SY0-701) exam. This 10-question practice test covers everything from security principles and controls to governance and threat actors. Perfect for on-the-go studying!🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥0:00: Introduction to Domain 1: General Security Concepts.0:06: Overview of the exam weight (12% of total score) 0:21: Q11:05: Q21:48: Q32:26: Q43:03: Q53:49: Q64:29: Q75:03: Q85:51: Q96:31: Q107:18: secguy.org7:27: secguy.org/exam-simulators7:36: secguy.org/discordTopic Categories: Information Technology, Cybersecurity, EducationKey Topics Covered:CIA Triad: Confidentiality, Integrity, AvailabilityAAA Framework: Authentication, Authorization, AccountingSecurity Control Types: Physical, Technical, Managerial, OperationalSecurity Models: Zero Trust, Defense in DepthProcesses: Change Management, Hashing, Digital Signatures#comptiasecurityplus #Security+ #cybersecurity #training #itcertification #Certifications #Sec GuyOriginal Sec Guy video: https://www.youtube.com/watch?v=_ajWLFMzxS0 -
Threat Vectors & Attack Surfaces Explained 17.09.2026 5минA "Threat Vector" is the path; an "Attack Surface" is the target. If you can't distinguish between a message-based attack (Smishing) and a file-based attack (Malicious Macro), you will lose points on your exam and miss threats in your SOC. In this video, Sec Guy maps out the 7 critical threat vectors you need to know, from Supply Chain compromises to Voice-based social engineering.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Message, Image, File, Voice, Supply Chain)[ ] Domain 2.4: Social Engineering (Phishing, Vishing, Smishing)CISSP[ ] Domain 1: Security and Risk Management (Threat Modeling & Attack Surface Analysis)CISM[ ] Domain 2: Information Risk Management (Vulnerability & Threat Identification)CRISC[ ] Domain 2: IT Risk Assessment (Threat Vectors & Emerging Risks)CCSP[ ] Domain 1: Cloud Concepts (Supply Chain Risk in Cloud Services)SecurityX (CompTIA)[ ] Domain 3.0: Security Operations (Analyzing Attack Vectors)GIAC GSEC (SANS)[ ] Incident Handling & Threat Intelligence: Attack VectorsAWS CSS (Certified Security – Specialty)[ ] Domain 1: Threat Detection (Identifying Compromise Vectors)Pentest+ (CompTIA)[ ] Domain 1: Planning and Scoping (Attack Surface Mapping)CEH (Certified Ethical Hacker)[ ] Domain 1: Information Security Overview (Attack Vectors & Surfaces)SecAI+[ ] AI Security: Prompt Injection as a "Message-Based" Vector[Timestamps]0:00 - Intro: Vectors vs. Surfaces0:50 - Vector 1: Message-Based (Phishing, Smishing, BEC)1:36 - Vector 2: Unsecure Networks (Rogue AP, Evil Twin)2:17 - Vector 3: Social Engineering (Psychological Manipulation)2:52 - Vector 4: File-Based (Macros, PDF Payloads)3:28 - Vector 5: Voice Call (Vishing, MFA Fatigue)4:03 - Vector 6: Supply Chain (Compromised Vendors/Updates)4:43 - Vector 7: Vulnerable Software (Zero Days, Unpatched Systems)5:14 - Summary: Identifying the Path to the Asset5:40 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=gl3wbHTC7TY -
Infrastructure Attack Surfaces: Spectre, VM Escape, & Memory Mastery 17.09.2026 7минSoftware updates are great, but you can't patch a physics problem. In this video, Sec Guy explores the Infrastructure Attack Surface, explaining why Spectre and Meltdown exploit the CPU itself, how VM Escape can bring down an entire cloud provider, and the critical difference between a Buffer Overflow (Execution Attack) and a Memory Leak (Availability Attack).🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 3.2: Virtualization and Cloud Computing (VM Escape, VM Sprawl)[ ] Domain 4.2: Embedded and Specialized Systems (TPM, HSM)[ ] Domain 2.2: Vulnerabilities (Buffer Overflow, Memory Leak, DLL Injection)[ ] Domain 3.4: Mobile Device Management (Jailbreaking, Rooting, Sideloading)CISSP[ ] Domain 3: Security Architecture (Side-Channel Attacks, Trusted Foundry, Ring Protection)[ ] Domain 8: Software Development Security (Buffer Overflows & Memory Safety)CISM[ ] Domain 3: Information Security Program (Infrastructure Protection & Supply Chain)CRISC[ ] Domain 2: IT Risk Assessment (Hardware & Virtualization Risks)CCSP[ ] Domain 1: Cloud Concepts (Hypervisor Security & Guest Escape)[ ] Domain 3: Cloud Infrastructure Security (Virtualization Risks)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Hardware Root of Trust & Secure Boot)GIAC GSEC (SANS)[ ] Virtualization & Cloud Security: VM Escape & Hypervisor AttacksAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (Host Isolation & Nitro Enclaves)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Exploiting Buffer Overflows & Mobile Devices)CEH (Certified Ethical Hacker)[ ] Domain 6: System Hacking (Privilege Escalation & DLL Injection)[ ] Domain 12: Mobile Platform Hacking (Jailbreaking & Rooting)SecAI+[ ] AI Security: Hardware Security (Protecting AI Model Weights on GPUs)[Timestamps]0:00 - Intro: You Can't Patch Physics0:45 - Hardware Roots of Trust: UEFI, TPM vs. HSM1:38 - Side-Channel Attacks: Spectre & Meltdown (Speculative Execution)2:07 - Supply Chain Interdiction2:25 - Virtualization Attacks: VM Sprawl vs. VM Escape (Hyperjacking)3:20 - Physical Memory Attacks: Rowhammer (Bit Flipping)3:45 - Memory Vulnerabilities: Buffer Overflow vs. Memory Leak4:40 - DLL Injection & Privilege Escalation5:05 - Mobile Security: Jailbreaking, Rooting, & Sideloading5:48 - Defense: MDM & Containerization (Samsung Knox)6:18 - Summary: Prioritizing Infrastructure Risk6:48 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=eu_viSkgSRU -
Network Architecture: OSI Model, TCP/IP Model, PEP/PDP VLANS Explained 17.09.2026 5минIf you can't map an attack to its layer, you can't defend against it. Is a DDoS attack Layer 4 or Layer 7? Is ARP Poisoning Layer 2 or Layer 3? In this video, Sec Guy breaks down the OSI Model vs. TCP/IP, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) in Zero Trust, and shows you how to stop VLAN Hopping attacks.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+[ ] Domain 3.1: Secure Network Architecture (OSI Model, TCP/IP, VLANs)[ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP)CISSP[ ] Domain 4: Communication & Network Security (OSI Layers & Secure Design)[ ] Domain 3: Security Architecture (Zero Trust Principles)CISM[ ] Domain 3: Information Security Program (Network Infrastructure Security)CRISC[ ] Domain 2: IT Risk Assessment (Network Vulnerabilities & Architecture Risks)CCSP[ ] Domain 3: Cloud Infrastructure Security (Virtual Networking & VLANs)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Network Segmentation & Zero Trust)GIAC GSEC (SANS)[ ] Network Security Essentials: OSI, TCP/IP, & Defense in DepthAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (VPC Design, Direct Connect vs. VPN)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (VLAN Hopping & ARP Poisoning)CEH (Certified Ethical Hacker)[ ] Domain 3: Scanning Networks (Mapping Attacks to OSI Layers)SecAI+[ ] AI Security: AI-Driven Network Segmentation & Anomaly Detection[Timestamps]0:00 - Intro: The Battlefield of Architecture0:36 - The OSI Model (7 Layers): "Please Do Not Throw Sausage Pizza Away"1:01 - The TCP/IP Model (4 Layers): "All The Internet Needs"1:25 - Mapping Attacks: DDoS (L7) vs. ARP Poisoning (L2)1:50 - Hybrid Cloud: Site-to-Site VPN vs. Direct Connect2:40 - The Death of the Flat Network: VLANs & 802.1Q2:58 - Zero Trust Brain: Policy Decision Point (PDP) vs. Enforcement Point (PEP)3:33 - Attack Vector: VLAN Hopping & Auto-Trunking4:00 - Defense: Deception Technology (Honeynets)4:16 - The Future: AI-Driven Dynamic Segmentation4:52 - Summary: Segment Ruthlessly5:08 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=i-jwtB3puxY -
Modern Network Security: From Firewalls to Agentic AI Defense 17.09.2026 7минA firewall is no longer just a box—it's a policy enforcement engine. In this deep dive, Sec Guy explains why WAFs have evolved into WAAPs to stop API attacks, why VPNs are being replaced by ZTNA and SASE, and how to use "Sticky MAC" and 802.1X to lock down your physical ports. If you are prepping for Security+, CISSP, or CCSP, this is your masterclass in network defense.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ (SY0-701)[ ] Domain 3.3: Network Designs (SASE, ZTNA)[ ] Domain 2.3: Indicators of Malicious Activity (Heuristic vs. Anomaly)[ ] Domain 1.2: Security Controls (NGFW, WAF/WAAP)CISSP[ ] Domain 3: Security Architecture (Radius vs. TACACS+, 802.1X)[ ] Domain 4: Communication & Network Security (Secure Design Principles)CISM[ ] Domain 3: Information Security Program (Infrastructure Protection)CRISC[ ] Domain 2: IT Risk Assessment (Network Vulnerabilities)CCSP[ ] Domain 1: Cloud Concepts (SASE, CASB)[ ] Domain 2: Cloud Data Security (DLP)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Micro-segmentation & eBPF)GIAC GSEC (SANS)[ ] Access Control & Password Management: 802.1X & Port SecurityAWS CSS (Certified Security – Specialty)[ ] Domain 2: Infrastructure Security (Security Groups vs. NACLs vs. WAF)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Bypassing NAC, VLAN Hopping)CEH (Certified Ethical Hacker)[ ] Domain 6: Evading IDS, Firewalls, and HoneypotsSecAI+[ ] AI Security: Defending Against Agentic AI & Non-Human Identities (NHI)[Timestamps]0:00 - Intro: Weapons on the Wall0:30 - Firewalls vs. NGFW: Deep Packet Inspection0:48 - WAAP: Protecting APIs & Stopping Mass Assignment1:27 - IDS vs. IPS: Signature, Heuristic, & Anomaly Detection2:42 - The New Threat: Agentic AI & Low/Slow Recon2:54 - NDR & DNS Sinkholing: Catching Lateral Movement3:18 - Bot Management: Behavioral Fingerprinting3:40 - 802.1X: Supplicant, Authenticator, & Radius Server4:12 - Port Security: Sticky MAC & Loop Protection4:28 - RADIUS vs. TACACS+: The CISSP Distinction5:22 - The Shift: VPN vs. ZTNA (Identity Aware Proxies)5:48 - SASE: Converging SD-WAN, CASB, & DLP6:16 - Non-Human Identities (NHI) & Micro-segmentation (eBPF)7:11 - Summary: Identity is the New Perimeter7:25 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=T6wtE8hDmw0 -
Risk Management: BCP, DRP, RTO/RPO & Risk Math 17.09.2026 8минIn cybersecurity, we don't plan for if—we plan for when. In this video, Sec Guy explains why the old "3-2-1 Backup Rule" is no longer enough to stop ransomware, how to calculate the cost of a disaster using SLE, ARO, and ALE, and the critical difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP).🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 5.2: Risk Management Processes (SLE, ALE, ARO, Risk Acceptance)[ ] Domain 5.4: Redundancy & Backup (RTO, RPO, MTBF, MTTR, 3-2-1 Rule)CISSP[ ] Domain 1: Security and Risk Management (Quantitative Risk Analysis)[ ] Domain 7: Security Operations (BCP/DRP, Testing Strategies)CISM[ ] Domain 4: Information Security Incident Management (RTO/RPO Definition)CRISC[ ] Domain 4: Risk and Control Monitoring (Reliability Metrics: MTBF/MTTR)CCSP[ ] Domain 1: Cloud Concepts (Cloud-to-Cloud Backup & Immutability)SecurityX (CompTIA)[ ] Domain 5.0: Security Operations (Disaster Recovery Planning)GIAC GSEC (SANS)[ ] Incident Handling: Business Continuity & Disaster RecoveryAWS CSS (Certified Security – Specialty)[ ] Domain 4: Incident Response (Automated Backup & Restore)Pentest+ (CompTIA)[ ] Domain 1: Planning and Scoping (Impact Analysis)CEH (Certified Ethical Hacker)[ ] Domain 1: Information Security Overview (Risk Terminology)SecAI+[ ] AI Security: Immutable Backups (WORM) to Prevent Training Data Corruption[Timestamps]0:00 - Intro: Planning for "When," Not "If"0:35 - The Math of Risk: Qualitative vs. Quantitative Analysis1:13 - Calculating Risk: SLE, ARO, and ALE (The $10,000 Laptop Example)2:02 - Risk Treatment: Mitigate, Transfer, Avoid, Accept2:40 - BCP Metrics: Maximum Tolerable Downtime (MTD) vs. RTO3:28 - Business Impact Analysis (BIA) & Supply Chain Risk4:00 - Testing the Plan: Tabletop vs. Full Interruption4:40 - The Golden Metrics: RTO (Time) vs. RPO (Data Loss)5:25 - Reliability Metrics: MTBF vs. MTTR6:02 - The New Standard: 3-2-1-1-0 Backup Rule (Air-Gapped & Verified)7:00 - Recovery Sites: Hot, Warm, Cold & Cloud7:52 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=7E1qTrSz2LU -
Identity Access Management: PAM, JIT, JEA, ABAC, SAML, OAuth 17.09.2026 5минIn a cloud-native world, firewalls don't matter if your identity is compromised. "Identity is the New Perimeter." In this video, Sec Guy explains why Permanent Admin Rights are a security failure, how to implement Just-in-Time (JIT) access to stop attackers, and clearly defines the difference between SAML (XML/Enterprise), OAuth (Authorization), and OIDC (Authentication).🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+[ ] Domain 1.3: Identity and Access Management (SAML, OAuth, OIDC, ABAC vs. RBAC)[ ] Domain 1.4: Access Control Schemes (PAM, JIT, JEA)CISSP[ ] Domain 5: Identity and Access Management (Federated Identity, SAML, OIDC, Authorization vs. Authentication)CISM[ ] Domain 3: Information Security Program (Identity Lifecycle & Access Governance)CRISC[ ] Domain 2: IT Risk Assessment (Privileged Access Risks)CCSP[ ] Domain 4: Cloud Application Security (Federated Identity Management & XML/JSON usage)SecurityX (CompTIA)[ ] Domain 1.0: Security Architecture (Implementing Zero Trust Identity)GIAC GSEC (SANS)[ ] Access Control & Password Management: Federation & OAuthAWS CSS (Certified Security – Specialty)[ ] Domain 3: Infrastructure Security (IAM Roles, Federation, & Temporary Credentials)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Token Theft & Forging SAML Assertions)CEH (Certified Ethical Hacker)[ ] Domain 6: System Hacking (Privilege Escalation via Misconfigured IAM)SecAI+[ ] AI Security: Workload Identity Federation for AI Agents (Non-Human Identities)[Timestamps]0:00 - Intro: Identity is the New Perimeter0:32 - Privileged Access Management (PAM): The Keys to the Kingdom1:00 - Just-In-Time (JIT) vs. Just-Enough-Administration (JEA)1:56 - ABAC vs. RBAC: Why Context Matters (Time/Location/Device)2:32 - Federated Identity: Moving Trust Across the Internet2:45 - SAML (XML): The Enterprise SSO Standard3:05 - OAuth 2.0 (Authorization): "What You Can Do" vs. "Who You Are"3:22 - OIDC (Authentication): The JSON Layer on Top of OAuth3:42 - The Cryptography of Tokens: Signing & Hashing (JWTs)4:42 - Non-Human Identities (NHI): Securing AI Agents & Service Accounts5:14 - Summary: Identity is Proof, Not Just a Username5:31 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=y_2UfJnrYtM -
Cryptography: PKI & Certificates: CA, OSCP, CRL, TLS 17.09.2026 5минEncryption protects your data, but PKI protects your trust. If you don't understand how a Certificate Authority (CA) validates a server, or why OCSP Stapling is faster than a CRL, you don't understand how the internet works. In this video, Sec Guy breaks down the "Trust Anchor" model, explains the difference between the Root CA and Intermediate CA, and walks you through the modern TLS 1.3 Handshake.🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥[Exam Ready Route - FREE]Pass your certification for $0.✅ Training Videos & Practice Tests✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)✅ Discord Access (Study sessions & Industry networking)👉 Start Here: https://secguy.org[Job Ready Route - MEMBERSHIP]Stop studying and start working. Get the hands-on experience hiring managers are asking for.🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs🔥 Salary Negotiator Workshop🔥 Experience Builder: Real-world projects to fill your resume👉 Get Hired: https://secguy.org[Exam Domain Checklist]This video covers critical objectives for the following exams:Security+ [ ] Domain 1.1: Cryptographic Concepts (PKI, CA, RA, CRL, OCSP)[ ] Domain 3.1: Secure Network Architecture (TLS 1.3, SSL Inspection)CISSP[ ] Domain 3: Security Architecture (PKI Trust Models, Key Management Lifecycle)[ ] Domain 4: Communication & Network Security (Secure Protocols - TLS)CISM[ ] Domain 2: Information Risk Management (Managing Trust & Digital Certificates)CRISC[ ] Domain 2: IT Risk Assessment (Risks of Expired Certificates & Weak CAs)CCSP[ ] Domain 2: Cloud Data Security (Key Management Services & BYOK)SecurityX (CompTIA)[ ] Domain 2.0: Security Architecture (Implementing Enterprise PKI)GIAC GSEC (SANS)[ ] Cryptography: Public Key Infrastructure & CertificatesAWS CSS (Certified Security – Specialty)[ ] Domain 2: Data Protection (AWS Certificate Manager - ACM & Private CA)Pentest+ (CompTIA)[ ] Domain 3: Attacks and Exploits (Certificate Pinning Bypass & MITM)CEH (Certified Ethical Hacker)[ ] Domain 4: Cryptography (PKI Attacks & Fake Certificates)SecAI+[ ] AI Security: Signing AI Models with PKI for Integrity[Timestamps]0:00 - Intro: The Problem with Public Keys (Trust)0:27 - The Certificate Authority (CA): The Ultimate Trust Anchor1:04 - Hierarchy of Trust: Root CA (Offline) vs. Intermediate CA1:36 - The Registration Authority (RA): Verifying Identity vs. Signing2:08 - Revocation: CRL (Slow List) vs. OCSP (Fast Query)2:50 - OCSP Stapling: The Efficient Modern Standard3:07 - TLS 1.3 Handshake: Asymmetric for Key Exchange, Symmetric for Data3:48 - Certificate Transparency Logs (CT Logs) & Post-Quantum Crypto4:28 - How to Build Your Own CA (Lab)4:53 - Outro: Stay Safe, Stay Secure.Original Sec Guy video: https://www.youtube.com/watch?v=HMazc2OpIeo
Популаран у
Овај подкаст се појављује и у подкаст листама ових земаља.